CVE-2022-3989

CVE-2022-3989

The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim’s WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.

Source: CVE-2022-3989

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다